PT-2025-49979 · WordPress · Profilepress

Published

2025-12-09

·

Updated

2025-12-14

·

CVE-2025-13642

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProfilePress versions through 4.16.7
Description The ProfilePress plugin for WordPress is susceptible to arbitrary shortcode execution due to inadequate input sanitization of the type parameter within the form preview functionality. This allows authenticated attackers with Subscriber-level access or higher to execute arbitrary shortcodes through the pp preview form API endpoint.
Recommendations Update ProfilePress to a version newer than 4.16.7.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13642

Affected Products

Profilepress